This topic only applies to Armor Complete users who are account administrators and new to the Armor Management Portal (AMP).
Before you begin, Armor recommends that you review pre-installation / pre-deployment information, such as virtual machine offerings and supported browsers.
To learn more, see Pre-deployment considerations for Armor Complete.
Step 6: Create A Firewall Rule with A New IP Address Group
Step 1: Create an IP Group
In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several IP addresses or just a single IP address.
You can combine related IP addresses into a single IP Group. For example, if you want to block traffic from three separate IP address, you do not have to create three separate firewall rules. Instead, you can combine the three separate IP addresses into a single, configurable IP Group. Then, when you create a firewall rule, you can pick the newly created IP Group as your Source or Destination IP addresses.
In the Armor Management Portal (AMP), on the left-side navigation, click Security.
Click Firewall.
If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.
- Click IP Groups.
- Click Actions, and then click New Group.
- In IP Group Name, enter a descriptive name.
- Armor recommends that you add Source or Destination into the name of the IP Group to help you identify the IP Group as the Source or Destination IP group.
- In Add Members To Group, enter a member, and then click the plus icon.
- You can enter:
- A single IP address
- A range of IP addresses
- CIDR
- You must add at least one member.
- You can add multiple members to a service group.
- You can enter:
- Click Apply.
- The newly created IP group will appear at the bottom of the table.
Step 2: Create a Service Group
In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several protocols (and ports).
You can combine related protocols (and ports) into a Service Group. For example, if you want to create a firewall rule to block three types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three types of traffic (protocols and ports) into a single, configurable Service Group. Then, when you create a firewall rule, you can pick the newly created Service Group.
In the Armor Management Portal (AMP), on the left-side navigation, click Security.
Click Firewall.
If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.
- Click Service Groups.
- Click Actions, and then click New Group.
- In Service Group Name, enter a descriptive name.
- In Add Members To Group, enter the service or sub-protocol, and then click the plus ( + ) icon.
- You must add at least one member.
- You can add multiple members to a service group.
Service or sub-protocol
Notes
Example
Services (TCP, UDP, etc.) You must enter a port number.
These services are not case-sensitive.
- tcp/80
- TCP/80
- Tcp/80
- tCp/80
Additional services (AARP, AH, etc.) These additional services are not case-sensitive.
Do not enter a port number with these additional services.
- ATALK
- igmp
- Gre
Sub-protocols (echo-reply, redirect, etc.) You must enter icmp, followed by the specific sub-protocol.
You must enter the sub-protocol in lower-case letters.
Do not enter a port number.
- icmp/source-host-isolated
- icmp/time-exceeded
- Click Apply.
- The newly created service group will appear at the bottom of the table.
For a complete list of supported services and sub-protocol, see Review supported services and sub-protocols.
Step 3: Create a Firewall Rule
In the Armor Management Portal (AMP), on the left-side navigation, click Security.
Click Firewall.
If you have virtual machines in various data centers, then in the top menu, click the corresponding data center.
Click Actions, and then click New Rule.
- If you do not see Actions, then click Create a Firewall Rule.
- In Name, enter a descriptive name.
- In Action, select Allow to allow specified traffic to access your virtual machine or Block to block specified traffic.
- Under Service, enter and select the name of the desired Service Group.
- To learn how to create a Service Group, see Create a service group.
- Under Source, enter and select the name of the desired IP Group.
- To learn how to create an IP Group, see Create an IP group.
- Under Destinations, in the field, enter and select the name of the desired IP Group.
- Click Save Rule.
After you create a rule, Armor recommends that you place the rule in the correct order.
If you are not familiar with ordering rules, contact Armor Support to help you properly order your firewall rules. It is extremely important to order rules in order to receive desired traffic.
To learn how to send a support ticket, see Support Tickets.
Reorder a Rule:
- Under Rule, in the numbered fields, enter a number to move the rule to a different position.
- If you have more than 25 rules, the additional rules will be placed in a secondary section within the Firewallscreen. To reorder and move these additional rules into a higher position, enter a number under the Ordercolumn, and then press Enter on your keyboard.
- In the top menu that appears, click Save.
Disable a Rule:
- Locate and hover over the desired rule.
- Click the vertical ellipses.
- Click Disable Rule.
- Click Disable Rule again.
- In the top menu that appears, click Save.
Step 7: Create A Role and Add Permissions
In the Armor Management Portal (AMP), roles are similar to job titles that you can create and assign to your users. You can populate these roles with certain permissions. For example, you can create an Audit role, and then you can add specific permissions that will give the assigned user permission to access audit-related features.
By default, a new administrator account contains an Admin role with all the available permissions selected.
When you create a new user account, you must assign that user a role. You can assign a default role or create a new role.
There are three default permissions in AMP:
- Admin contains every permission in AMP.
- Technical contains mostly write-only permissions.
- Billing contains mostly read-only permissions.
If you want to use a default role, then you can skip to Step 8: Create An User and Assign A Role.
Step 8: Create An User and Assign A Role
Repeat Step 8: Create An User and Assign A Role for every user you want to invite.
Step 9: Enable SSL/VPN Access for Your Users
Step 10: Subscribe to Data Center Notifications
Step 11: Configure Your Notification Preferences
Armor recommends that you configure your account to receive notifications for Account, Billing, and Technical events.
These notification preferences do not relate to support tickets.
To update your notification preferences for support tickets, see Support Tickets.
Account | You will receive a notification when:
|
Billing | You will receive a notification when:
You can configure a user to become the primary billing contact for an account. This user will receive billing notifications. Additionally, this user will be listed in the Bill to field in an invoice.
|
Technical | You will receive a notification when:
|
You can only change the notification preferences for your own account. You cannot change the notification preferences for other user accounts.
- In the Armor Management Portal (AMP), in the top, right corner, click the vertical ellipses.
- Click Settings.
- Click Notification Preferences.
- Use the slider to make your desired changes.
- Select Alert to receive notifications in the top bar in the Armor Management Portal (AMP).
- Select Email to receive notifications through email.
- You can select both notification options.
- Click Update Notification Preference to save your changes.